fintech-agreement-drafting-stephane-boghossian

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional guidelines for legal drafting and does not contain any executable scripts, hidden code, or malicious logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to process user-provided legal drafts and has access to web search tools.
  • Ingestion points: The skill explicitly instructs the agent to 'Review an existing draft' provided by the user (SKILL.md).
  • Boundary markers: The skill implements a robust 'Scope Gate' at the start of the matter, providing clear warnings about data privilege and the limitations of AI-generated content.
  • Capability inventory: The skill has access to the Read, Write, Edit, WebFetch, and WebSearch tools to perform its tasks.
  • Sanitization: The instructions require the agent to use abstracted placeholders and explicitly forbid drafting representations as true without executed evidence.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file access patterns or unauthorized network data transmission were identified. Tool usage is consistent with the stated purpose of fetching regulatory information and managing contract drafts.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns attempting to bypass agent safety filters or override core behavioral guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:32 PM
Security Audit — agent-trust-hub — fintech-agreement-drafting-stephane-boghossian